Highly Evasive Targeted Bit-Trojan on Deep Neural Networks

被引:0
|
作者
Jin, Lingxin [1 ]
Jiang, Wei [1 ]
Zhan, Jinyu [1 ]
Wen, Xiangyu [2 ]
机构
[1] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
[2] Chinese Univ Hong Kong, Dept Comp Sci & Engn, Hong Kong 999077, Peoples R China
关键词
Deep neural networks; bit-flip attack; Trojan attack; targeted bit-Trojan;
D O I
10.1109/TC.2024.3416705
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Bit-Trojan attacks based on Bit-Flip Attacks (BFAs) have emerged as severe threats to Deep Neural Networks (DNNs) deployed in safety-critical systems since they can inject Trojans during the model deployment stage without accessing training supply chains. Existing works are mainly devoted to improving the executability of Bit-Trojan attacks, while seriously ignoring the concerns on evasiveness. In this paper, we propose a highly Evasive Targeted Bit-Trojan (ETBT) with evasiveness improvements from three aspects, i.e., reducing the number of bit-flips (improving executability), smoothing activation distribution, and reducing accuracy fluctuation. Specifically, key neuron extraction is utilized to identify essential neurons from DNNs precisely and decouple the key neurons between different classes, thus improving the evasiveness regarding accuracy fluctuation and executability. Additionally, activation-constrained trigger generation is devised to eliminate the differences between activation distributions of Trojaned and clean models, which enhances evasiveness from the perspective of activation distribution. Ultimately, the strategy of constrained target bits search is designed to reduce bit-flip numbers, directly benefits the evasiveness of ETBT. Benchmark-based experiments are conducted to evaluate the superiority of ETBT. Compared with existing works, ETBT can significantly improve evasiveness-relevant performances with much lower computation overheads, better robustness, and generalizability. Our code is released at https://github.com/bluefier/ETBT.
引用
收藏
页码:2350 / 2363
页数:14
相关论文
共 50 条
  • [41] A Survey of Neural Trojan Attacks and Defenses in Deep Learning
    Wang, Jie
    Hassan, Ghulam Mubashar
    Akhtar, Naveed
    arXiv, 2022,
  • [42] A General Hardware Trojan Technique Targeted on Lightweight Cryptography with Bit-Serial Structure
    Yang, Yijun
    Wu, Liji
    Yuan, Ye
    Zhang, Xiangmin
    Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST, 2019, 284 : 647 - 655
  • [43] CleaNN: Accelerated Trojan Shield for Embedded Neural Networks
    Javaheripi, Mojan
    Samragh, Mohammad
    Fields, Gregory
    Javidi, Tara
    Koushanfar, Farinaz
    IEEE/ACM International Conference on Computer-Aided Design, Digest of Technical Papers, ICCAD, 2020, 2020-November
  • [44] Hardware Trojan Detection using Graph Neural Networks
    Yasaei, Rozhin
    Chen, Luke
    Yu, Shih-Yuan
    Faruque, Mohammad Abdullah Al
    IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024, : 1 - 1
  • [45] CLEANN: Accelerated Trojan Shield for Embedded Neural Networks
    Javaheripi, Mojan
    Samragh, Mohammad
    Fields, Gregory
    Javidi, Tara
    Koushanfar, Farinaz
    2020 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER AIDED-DESIGN (ICCAD), 2020,
  • [46] Hardware Trojan Detection using Graph Neural Networks
    Yasaei, Rozhin
    Chen, Luke
    Yu, Shih-Yuan
    Al Faruque, Mohammad Abdullah
    arXiv, 2022,
  • [47] Hardware Trojan Detection Using Graph Neural Networks
    Yasaei, Rozhin
    Chen, Luke
    Yu, Shih-Yuan
    Al Faruque, Mohammad Abdullah
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2025, 44 (01) : 25 - 38
  • [48] A Power Efficient Multi-Bit Accelerator for Memory Prohibitive Deep Neural Networks
    Shivapakash, Suhas
    Jain, Hardik
    Hellwich, Olaf
    Gerfers, Friedel
    2020 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2020,
  • [49] Ultra-Low Precision 4-bit Training of Deep Neural Networks
    Sun, Xiao
    Wang, Naigang
    Chen, Chia-Yu
    Ni, Jia-Min
    Agrawal, Ankur
    Cui, Xiaodong
    Venkataramani, Swagath
    El Maghraoui, Kaoutar
    Srinivasan, Vijayalakshmi
    Gopalakrishnan, Kailash
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [50] Blind Data Adversarial Bit-flip Attack against Deep Neural Networks
    Ghavami, Behnam
    Sadati, Mani
    Shahidzadeh, Mohammad
    Fang, Zhenman
    Shannon, Lesley
    2022 25TH EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD), 2022, : 899 - 904